FATF Recommendations & FIU-India Reporting: IIBF Exam Guide
The FATF recommendations are the single most important framework to master for the IIBF KYC, AML and CFT certification, because almost every Indian anti-money-laundering rule you will be tested on traces back to them. When you understand how the Financial Action Task Force standards flow into India's Prevention of Money Laundering Act, the Financial Intelligence Unit - India (FIU-IND) reporting system, and the grey and black list consequences for banks, the exam stops feeling like memorisation and starts feeling like a story that connects. This guide rebuilds that story from the ground up so you can answer confidently in the hall.

Key takeaways
- The FATF recommendations are 40 global standards; India has been a full member since 2010.
- India implements them through the PMLA 2002 and the Maintenance of Records Rules, 2005.
- Four reports go to FIU-IND: STR, CTR, CCR and NTR - each with its own trigger and deadline.
- The risk-based approach drives customer categorisation (low, medium, high) and Enhanced Due Diligence.
- FATF grey and black lists force Indian banks to apply extra scrutiny on cross-border dealings.
What the FATF recommendations actually are
The FATF recommendations are the internationally endorsed standards for fighting money laundering (ML), terrorist financing (TF) and the proliferation financing of weapons of mass destruction. The Financial Action Task Force itself is an intergovernmental policy-making body set up in 1989 at the G7 Summit in Paris, and its standards now shape the laws of more than 200 countries and jurisdictions through FATF and its regional bodies.
Originally numbering 40 and revised periodically, the recommendations are not a treaty you sign once. They are a living rulebook, each supported by detailed Interpretive Notes that explain how the standard should work in practice. India became a full FATF member in 2010, and from that point the obligation to align domestic law with these standards became central to how Indian banks operate.
The structure of the 40 FATF recommendations
For the exam, you rarely need to recite individual recommendation numbers word for word. What examiners reward is knowing which thematic pillar a topic belongs to. The 40 recommendations are grouped as follows:
- AML/CFT policies and coordination (R.1-2): countries assess their ML/TF risks and adopt a risk-based approach, coordinated across all competent authorities.
- Money laundering and confiscation (R.3-4): criminalise ML in line with the Vienna and Palermo Conventions, and enable confiscation of proceeds of crime.
- Terrorist financing and proliferation (R.5-8): criminalise TF, implement UN Security Council targeted financial sanctions without delay, and protect non-profit organisations from misuse.
- Preventive measures (R.9-23): the largest cluster - Customer Due Diligence (CDD), record-keeping, Politically Exposed Persons (PEPs), correspondent banking, wire transfers, new technologies, reliance on third parties and DNFBPs.
- Transparency and beneficial ownership (R.24-25): legal persons and arrangements must hold accurate, current information on their beneficial owners.
- Powers and responsibilities of competent authorities (R.26-35): establish FIUs, law-enforcement agencies and supervisors with real powers, including information sharing.
- International cooperation (R.36-40): provide mutual legal assistance, extradition and prompt exchange of information.
If you can place any obligation - say, PEP screening or wire-transfer rules - into the Preventive Measures pillar, you are already ahead of most candidates. For a deeper drill on these definitions, work through the KYC, AML and CFT subject hub and reinforce them with the full KYC-AML course path.
The risk-based approach and how India applies it
The risk-based approach (RBA) is the philosophical heart of the FATF recommendations. Instead of treating every customer with identical, rigid rules, the RBA asks institutions to identify, assess and understand the ML/TF risks they actually face, then apply effort proportionate to those risks. Scarce compliance resources are pointed where the threat is greatest.
National Risk Assessment
India conducts National Risk Assessments (NRAs) under FATF guidance. The Ministry of Finance, RBI, SEBI, IRDAI, the Department of Revenue and other agencies jointly map the country's exposure to threats such as drug trafficking, corruption, cybercrime and tax evasion. These findings feed directly into India's national AML/CFT strategy and the supervisory risk ratings assigned to different sectors.
Customer risk categorisation
Under the PMLA and the rules made under it, every reporting entity - banks, NBFCs, insurers, mutual funds, stock brokers and payment operators - must classify customers into risk bands:
- Low risk: salaried individuals with regular income, government departments, and listed companies with transparent ownership.
- Medium risk: private companies, trusts, individuals with variable income, and foreign nationals with genuine business.
- High risk: PEPs and their close associates, customers from high-risk jurisdictions, customers whose KYC cannot be completed satisfactorily, and high-value non-face-to-face dealings.
High-risk customers attract Enhanced Due Diligence (EDD), more frequent KYC updates and senior-management approval. RBI's Master Direction on KYC maps neatly onto FATF's recommendations on CDD and PEPs, so the two should be studied side by side rather than in isolation.
India's PMLA reporting obligations: STR, CTR, CCR and NTR
This is the most heavily tested area of the whole certification, so spend extra time here. India's reporting framework sits inside the Prevention of Money Laundering Act, 2002 and the Prevention of Money Laundering (Maintenance of Records) Rules, 2005, and it flows directly from the FATF recommendations on suspicious-transaction reporting and on operating an FIU. Four report types must be filed with FIU-IND.
Suspicious Transaction Report (STR)
An STR is filed whenever a reporting entity has reason to believe a transaction - regardless of amount - involves proceeds of crime, relates to terrorist financing, or is an attempt to dodge reporting thresholds. There is no monetary minimum; the trigger is qualitative suspicion. It must be filed within 7 days of forming that suspicion, which is why banks invest heavily in transaction-monitoring systems that flag patterns like structuring (smurfing) or sudden cash inconsistent with the customer profile.
Cash Transaction Report (CTR)
A CTR covers all cash deposits or withdrawals exceeding ₹10 lakh, individually or in aggregate within a calendar month. It is filed by the 15th of the following month. The threshold is set high enough to capture significant movements without drowning the system in small, routine transactions.
Counterfeit Currency Report (CCR)
A CCR is filed whenever counterfeit Indian currency is detected, in any amount, and it must reach FIU-IND within 3 working days of detection. This data helps RBI and law enforcement map and trace the circulation of fake notes.
Non-Profit Organisation Transaction Report (NTR)
An NTR covers cash transactions exceeding ₹10 lakh by non-profit organisations. The logic comes straight from the FATF recommendation on protecting NPOs from terrorist-financing misuse, and these reports help FIU-IND watch large cash flows through the charitable and religious sectors.
| Report | Trigger | Threshold | Filing deadline |
|---|---|---|---|
| STR | Suspicion of ML/TF | No minimum | Within 7 days of suspicion |
| CTR | Cash transaction | Above ₹10 lakh/month | 15th of following month |
| CCR | Counterfeit currency detected | Any amount | Within 3 working days |
| NTR | NPO cash transaction | Above ₹10 lakh | 15th of following month |
Drill these four until the triggers, thresholds and deadlines are automatic. A timed run on the KYC-AML mock tests is the fastest way to lock them in, and the KYC-AML matching game is excellent for the STR-versus-CTR distinction that trips up so many candidates.

FIU-IND: India's financial intelligence hub
The Financial Intelligence Unit - India (FIU-IND) was established on 18 November 2004 under the Department of Revenue, Ministry of Finance. It is the nodal agency for receiving, processing, analysing and disseminating financial intelligence, and its very existence is required by the FATF recommendation that every country operate an FIU.
What FIU-IND does
- Collection: receives STRs, CTRs, CCRs and NTRs from all reporting entities registered under the PMLA.
- Analysis: identifies patterns, trends and networks through tactical and strategic analysis.
- Dissemination: shares intelligence with agencies such as the Enforcement Directorate, CBI, Income Tax Department and NCB, and with foreign FIUs.
- Compliance: monitors reporting entities and can impose penalties of up to ₹1 lakh per day of default for non-filing or delayed filing.
- International cooperation: exchanges intelligence with foreign FIUs under Memoranda of Understanding.
FIU-IND is a member of the Egmont Group, the global network of financial intelligence units, which provides a secure channel for cross-border information sharing - vital for tracing laundering schemes that hop across jurisdictions. Reporting entities, from banks and NBFCs to jewellers and real-estate agents above the prescribed limits, must register on the FIU-IND portal, and failure to register is itself a PMLA violation.
FATF mutual evaluations and India's assessment
The FATF recommendations gain teeth through the mutual evaluation process, a peer review in which trained evaluators from other member countries assess a nation against all 40 recommendations. Crucially, evaluations test two things: technical compliance (are the laws and regulations in place?) and effectiveness (does the system actually work in practice, judged across 11 Immediate Outcomes?).
India underwent its 4th-round mutual evaluation in 2023-24. The assessment recognised India's strong legal architecture - PMLA, FEMA, UAPA and the NDPS Act - while flagging areas for improvement such as beneficial-ownership transparency and supervision of DNFBPs like real estate and jewellers. Strong outcomes help India maintain its standing as a cooperative, compliant jurisdiction, which directly supports cross-border banking and correspondent relationships. For the exam, always confirm the latest outcome wording against the official FATF and IIBF material, since assessment follow-ups continue over time.
FATF grey list and black list: the impact on Indian banks
Two FATF watchlists turn the recommendations into real economic pressure, and both are common exam fodder.
Grey list - increased monitoring
The grey list, formally Jurisdictions Under Increased Monitoring, names countries that have committed to fixing identified strategic deficiencies on an agreed timeline. Grey-listing does not automatically trigger sanctions, but it does prompt financial institutions worldwide - including Indian banks - to apply Enhanced Due Diligence on dealings with those jurisdictions.
Black list - call for action
The black list, formally High-Risk Jurisdictions Subject to a Call for Action, names countries whose deficiencies pose a severe threat to the international financial system. Iran and the DPRK (North Korea) have historically been the primary entries. For these, FATF calls on members to apply counter-measures, which can mean enhanced scrutiny, restrictions, or in some cases refusing transactions altogether.
Why correspondent banking feels it first
When a counterpart jurisdiction is listed, Indian banks must review their correspondent relationships there, which ripples into trade finance, SWIFT transfers and remittance corridors. Compliance teams track FATF plenary announcements and update transaction-monitoring rules and customer risk ratings accordingly. Because the specific countries on each list change after each plenary, treat any list as time-sensitive and verify the current position on the official IIBF website and FATF publications before the exam.
A practical study plan for this topic
Cramming rarely works for a procedural subject like this. A staged plan does:
- Days 1-2 - the map: learn the seven pillars and what each covers. Aim to slot any concept into the right pillar instantly.
- Days 3-4 - the reports: memorise STR, CTR, CCR and NTR triggers, thresholds and deadlines using the table above, then test recall actively.
- Day 5 - the institutions: nail FIU-IND's functions, the Egmont link and the penalty for default.
- Day 6 - the consequences: distinguish grey list from black list and the bank obligations that follow each.
- Day 7 - simulate: sit a full timed mock, review every wrong answer, and revisit weak pillars.
Spacing your revision and finishing with timed practice converts fragile recognition into exam-day recall. Browse every related explainer for this paper through the full KYC-AML guide library.
Common mistakes to avoid
- Confusing STR and CTR: an STR is suspicion-based with no threshold; a CTR is purely threshold-based at above ₹10 lakh a month. Mixing these up is the single most frequent error.
- Forgetting the NTR exists: many candidates name only three reports. Always include the NPO transaction report.
- Treating watchlists as permanent: grey and black lists are updated regularly. Memorise the concept and obligations, not a fixed country roster.
- Ignoring effectiveness: a mutual evaluation grades both technical compliance and real-world effectiveness across 11 Immediate Outcomes - not just whether laws exist.
- Studying RBI rules in a vacuum: RBI's KYC Master Direction maps onto the FATF recommendations, so learn them together rather than as separate silos.
Frequently asked questions
What are the FATF recommendations and why do they matter for Indian banks?
The FATF recommendations are 40 internationally agreed standards for countering money laundering, terrorist financing and proliferation financing, adopted across more than 200 countries and jurisdictions. They matter for Indian banks because India's PMLA, RBI's KYC Master Directions and SEBI/IRDAI AML guidelines directly implement them. Non-compliance can bring regulatory penalties, loss of correspondent relationships and reputational damage.
What is the difference between an STR and a CTR under the PMLA?
A Suspicious Transaction Report is filed when an entity forms a reasonable suspicion that a transaction, of any amount, is linked to money laundering or terrorist financing, and it must be filed within 7 days of that suspicion. A Cash Transaction Report is threshold-based, filed for all cash transactions above ₹10 lakh in a calendar month, whether or not anything looks suspicious. CTRs are filed by the 15th of the following month.
What is FIU-IND and how does it relate to FATF?
FIU-IND is India's national agency, established on 18 November 2004 under the Ministry of Finance, to receive, analyse and disseminate financial intelligence from reporting entities. Its existence is required by the FATF recommendation that every country operate a financial intelligence unit. FIU-IND is also a member of the Egmont Group, which enables secure cross-border intelligence sharing with foreign FIUs.
What happens when a country is placed on the FATF grey or black list?
Grey-listing means a country has committed to fix strategic AML/CFT deficiencies within agreed timelines, prompting institutions worldwide to apply Enhanced Due Diligence on dealings with it. Black-listing signals severe deficiencies, and FATF asks members to apply counter-measures that can restrict or even prohibit transactions. Indian banks respond by tightening scrutiny, seeking senior approval and reviewing correspondent relationships.
How many reports must Indian reporting entities file with FIU-IND?
There are four: the Suspicious Transaction Report (STR), Cash Transaction Report (CTR), Counterfeit Currency Report (CCR) and Non-Profit Organisation Transaction Report (NTR). Each has a distinct trigger, threshold and filing deadline. Knowing all four, and not just the first three, is essential for the exam.
Is memorising specific grey-list countries enough for the exam?
No, because the watchlists are revised after each FATF plenary, so a fixed list can quickly go out of date. Focus instead on understanding what grey and black listing mean and the obligations they impose on banks. For any current, date-sensitive position, confirm against the latest FATF and IIBF material before your exam.
Bringing it together
Once you can trace a single thread - from a FATF recommendation, into the PMLA, through a customer risk rating, to a report filed with FIU-IND, and out to the consequences of a watchlist - this entire topic becomes intuitive rather than intimidating. Study the pillars, the four reports and the two lists, then prove your recall under timed conditions. Put in that focused week, trust your preparation, and you will walk into the KYC, AML and CFT exam ready to score where it counts.
Related Guides
Continue building your AML/CFT mastery with these closely linked walkthroughs: FIU-India reporting: STR, CTR & CDD Guide for Exams, PMLA, FATF and the Customer Due Diligence Framework Explained, and STR and CTR Reporting to FIU-IND: A Banker's Guide.
📚 Free Learning Sessions resources — connect & crack your exam
- 📝 Free mock tests — chapter-wise, exam-pattern, with instant solutions
- 🎮 Matching games — gamified revision of key terms & concepts
- 📄 Study notes & PDFs — downloadable chapter material
- 🎥 Video classes on YouTube — subscribe to @learningsessions
💬 Want the full course? WhatsApp your course name to 8360944207 and our team will set you up.
📱 Study on the go — get our iOS & Android app at iibf.store/app.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading